Home Malware Programs Rogue Anti-Spyware Programs PC Bug Remover Pro

PC Bug Remover Pro

Posted: March 29, 2010

PC Bug Remover Pro is a variant of the PC Bug Finder Pro rogue software. PC Bug Remover Pro performs a fake system scan and displays bogus restults. Victims will then be prompted with popup alerts to purchase the full version of PC Bug Remover Pro. Be careful when downloading video codecs and using flash players, as these provide a means for PC Bug Remover Pro to spread.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Documents and Settings%\[UserName]\Desktop\PC Bug Remover Pro.lnk
    2 %Documents and Settings%\All Users\Start Menu\Programs\PC Bug Remover Pro\
    3 %Documents and Settings%\All Users\Start Menu\Programs\PC Bug Remover Pro\PC Bug Remover Pro.lnk
    4 %Documents and Settings%\All Users\Start Menu\Programs\PC Bug Remover Pro\Remove PC Bug Remover Prov1.0.lnk
    5 %Program Files%\PCBugRemoverPro\
    6 %Program Files%\PCBugRemoverPro\PCBugRemoverPro.exe
    7 %Program Files%\PCBugRemoverPro\uninstal.log
    8 %WINDOWS%\System32\COMDLG32.OCX
    9 %WINDOWS%\System32\mscomctl.ocx
    10 %WINDOWS%\System32\msvbvm60.dll
    11 %WINDOWS%\unvise32.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Uninstall\PCBugRemoverProHKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\WindowsUpdate\Auto Update\ResultsHKEY_LOCAL_MACHINE\SOFTWARE\PCBugRemoverProHKEY..\..\..\..{RegistryKeys}HKEY_CLASSES_ROOT\CLSID\{1EFB6596-857C-11D1-B16A-00C0F0283628}\Implemented CategoriesHKEY_CLASSES_ROOT\Interface\{F08DF953-8592-11D1-B16A-00C0F0283628}\
Loading...